Chess.com Exposes 7.3M Advertiser Profiles in Third Data Leak in 3 Years. What Do Advertisers Know About You?

The leak offers a rare look at the hidden labels Chess.com uses to sort players for ads, trials and experiments.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

Your public Chess.com profile shows your username, country, and rating. The leaked version reveals something you cannot normally see: how Chess.com sorts you for advertisers.

A 15.5GB file posted on data-leak forums reportedly contains more than 7.3 million Chess.com records.[1] Each one includes internal advertising fields labeled trial eligibility, lapsed users, rating bands, and “coach-nudge” experiments.

Those labels do not appear on your profile or in Chess.com’s public API. There is no obvious setting to review or correct them, either.

That makes this more than another leak story. It offers a rare look at the commercial profile a free platform builds behind the scenes, including what Chess.com appears to have concluded about you.

In this article
What was exposed in the Chess.com leak?
Chess.com’s hidden advertiser profiles
Can you see what Chess.com knows about you?
Was Chess.com hacked?
What Chess.com users should do now

What was exposed in the Chess.com leak?

The file appeared on two unnamed data-leak forums on August 12, 2026. An analysis of the full dataset found 7,337,395 records, each with 38 fields. The data reportedly included:

  • Email addresses
  • Usernames, names, and account IDs
  • Countries, locations, and language settings
  • Chess titles, ratings, and skill levels
  • Premium membership details
  • Account creation and recent login dates
  • Internal advertising labels

About 75% of the records contained an email address. However, the leak likely affects fewer than 7.3 million individual players because roughly 7.4% of user IDs appeared more than once.

The data is also recent. It was collected between July 26 and August 3, sometimes capturing the same account on multiple days.

Researchers checked timestamps hidden inside Chess.com-issued account IDs against the registration dates listed in the file. Nearly every one matched, offering strong evidence that the data is real.

Chess.com had not publicly confirmed the leak at the time of writing.

Chess.com’s hidden advertiser profiles

Two fields make this leak particularly revealing: gam_audiences and audiences_member_of. Both reportedly contain Google Ad Manager audience segments, and every record had them filled in. The labels placed players into groups based on factors such as their rating, trial eligibility, or whether they had stopped using the platform.

In other words, Chess.com was sorting players into groups that could shape the promotions, experiments, or sales pitches they received.

Chess.com tells users that it collects plenty of behavioral information. Its privacy policy specifically mentions activity patterns, purchase history, products considered, ratings, club memberships, penalties, and complaints. It also says the company draws “inferences” from the information it collects.

For U.S. advertising, Chess.com says it may sell or share identifiers and online activity with advertising networks, data brokers, and other advertising companies. Its cookie policy also says tracking cookies can build interest profiles using activity on Chess.com and elsewhere online.

That tells you profiling happens. It does not show you the actual labels attached to your account. Agreeing to personalized ads may feel different when you learn you have been placed in a “lapsed-user” group or selected for a behavioral experiment.

Can you see what Chess.com knows about you?

Chess.com says its My Data page lets you view “all the account data” it stores.

However, its help page only specifically mentions information from your settings, mobile device data, and anti-fraud login details. It does not say whether your advertising segments will appear.

The usual privacy controls will not help much, either. They let you manage social features, such as who can challenge you or view your friends list, but not labels like “trial eligible.”

You can limit some targeted advertising by opening Privacy Settings in the Chess.com website footer and turning off Targeting Cookies. According to Chess.com, that’ll stop third-party ads from being personalized based on your interests.

This may not delete labels already attached to your account or affect groups used for Chess.com’s own promotions. The company has not explained how players can inspect, correct, or remove the segments found in the leak.

Depending on where you live, you may also have the right to request your personal information or ask Chess.com to correct/delete it.

Was Chess.com hacked?

The evidence points to automated scraping, rather than a break-in at Chess.com’s main database. Records were gathered in batches over nine days, with some accounts captured more than once — like a program repeatedly collecting data.

Still, one question remains. The internal advertising labels are not available through Chess.com’s public API, yet they appear in every record. The scraper may have reached an authenticated or otherwise non-public interface.

Only Chess.com can explain how those fields became accessible and whether someone bypassed its security controls.

In 2023, someone abused its find-friends feature to link external email addresses to Chess.com accounts. The resulting file contained 828,327 records. Days later, another collection affecting nearly 476,000 users was published.

A separate 2025 breach involving a third-party file-transfer app exposed information belonging to 4,541 people.

What Chess.com users should do now

There is no evidence that this leak contains passwords or anything else that would let someone sign in to your account. Resetting your password will not remove your information from the file.

The big concern here is phishing. A scammer who knows your account details could write a convincing message about a subscription renewal, tournament invitation, etc.

Avoid login links in unexpected emails. Open Chess.com through its app or type the address into your browser instead. Chess.com will not need your password or authentication code to investigate your account.

You should still use a unique password and enable two-factor authentication. This will protect you if the same email address appears in another leak that includes login credentials.

Finally, check Chess.com’s My Data page. If it does not show the advertising fields, you may be able to contact the company and request a complete copy of the personal information and inferences attached to your account.

This leak reveals the quiet bargain behind a free account: While you build a chess rating, the platform may be building an advertising rating of its own.

#1 Adblocker — Even Blocks YouTube Video Ads
5.0
Editorial Rating
Get Deal
On Total Adblock's website
2026 Editors’ Choice
Best Overall Ad Blocker
Ad Blocker
Total Adblock
PROMOTION: Get 80% Off
  • Top ad blocker that historically scores 100/100 on AdBlock Tester, passing every banner, interstitial, pop-up, and contextual ad test
  • Successfully blocked YouTube ads in our testing, one of the trickier platforms for ad blockers to handle consistently
  • Works across Chrome, Edge, Safari, and Opera, plus Android and iOS mobile apps

Author Details
Thomas Kent is a multi-disciplined reporter with over a decade of experience covering online platforms, digital trends, and consumer-facing tech. Tom focuses on digital privacy, data tracking, and user behavior, with a particular interest in how cookies, online surveillance, and platform design shape the modern internet experience. His reporting takes a research-driven, news-focused approach, translating complex technical topics into clear, accessible insights.

Citations

[1] 7.3M chess.com records leaked, and the data is real